Agent skill

Service Itsm Agentic Setup Itsm Agentforce Permset Assign

by forcedotcom in forcedotcom/sf-skills

Resolve missing ITSM Intelligence invocable actions so a Fulfiller NGA agent can activate.

Apache-2.0Auto-check: notesAI & LLM Engineering

Install Service Itsm Agentic Setup Itsm Agentforce Permset Assign

skills CLI
$ npx skills add forcedotcom/sf-skills --skill service-itsm-agentic-setup-itsm-agentforce-permset-assign -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install forcedotcom/sf-skills service-itsm-agentic-setup-itsm-agentforce-permset-assign --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/forcedotcom/sf-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/service-itsm-agentic-setup-itsm-agentforce-permset-assign .claude/skills/service-itsm-agentic-setup-itsm-agentforce-permset-assign && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
service-itsm-agentic-setup-itsm-agentforce-permset-assign
GitHub stars
1.1k
Token cost
~5.4k tokens
SKILL.md length
2,208 words
Files
8 (incl. scripts, references)
Skills in repo
252
Repo updated
First seen
Licence
Apache-2.0

At a glance

Resolve missing ITSM Intelligence invocable actions so a Fulfiller NGA agent can activate.

  • Works in 5 steps: Read: which Fulfiller persona permsets… → Assign path (Branch A) → Hand-off path (Branch B: no Fulfiller… → …
  • The Fulfiller agent-configure skill reports missing actions on activate
  • SKILL.md covers Scope, Mechanism, Four helper scripts (all… and Preconditions, plus 6 more sections
  • Runs JavaScript scripts from its folder; calls sf and node

What it does

Service Itsm Agentic Setup Itsm Agentforce Permset Assign is an agent skill from forcedotcom/sf-skills. Resolve missing ITSM Intelligence invocable actions so a Fulfiller NGA agent can activate. Reads which of the three Core Fulfiller persona permsets (IncidentFulfiller, ProblemFulfillerPermSet, ChangeRequestFulfillerPermSet) are provisioned, then assigns the running user the selected persona (plus backing PSL when license-gated) so svcitsmintelligence actions surface; hands off to service-itsm-agentic-setup-agentforce-studio-validate if none are provisioned. Use when the Fulfiller agent-configure skill reports…

Its SKILL.md is about 5.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 9 other files, including scripts and reference files (for example `references/cli-invocation.md`, `references/helper-contracts.md` and `references/permset-topology.md`).

It sits in AI & LLM Engineering, covering Prompt engineering. It works with Salesforce. The repository describes itself as: Salesforce's curated collection of agent skills for building applications. Optimized for Agentforce Vibes, compatible with all AI tools. The licence is Apache-2.0.

When your agent uses it

  • The Fulfiller agent-configure skill reports missing actions on activate
  • Invocable action svcitsmintelligenceX does not exist surfaces
  • A user asks to grant themselves Fulfiller prompt-template access
  • Asked to assign the Incident

Example prompts

  • “Invocable action svcitsmintelligenceX does not exist”
  • “/service-itsm-agentic-setup-itsm-agentforce-permset-assign”

Requirements

  • Node.js
  • Pre-approved tools (allowed-tools): Bash, Read, AskUserQuestion

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Read: which Fulfiller persona permsets are provisioned on this org?
  2. Assign path (Branch A)
  3. Hand-off path (Branch B: no Fulfiller persona provisioned)
  4. Verify
  5. Aggregate verdict

What it can do on your machine

Read from SKILL.md and the folder at commit 4bbae5c. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Bash
    • Read
    • AskUserQuestion

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 4 files in scripts/ (JavaScript), which the agent can run.

    Shell commands in SKILL.md call:

    • sf
    • node

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Service Itsm Agentic Setup Itsm Agentforce Permset Assign loads about 5.4k tokens when it runs, and up to ~9.6k if it reads all its reference files. Until then it costs about 265 tokens; SKILL.md has 2,208 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~265
When it runs · the whole SKILL.md, loaded when a task matches
~5.4k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~9.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Bash, Read, AskUserQuestion, 

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from forcedotcom/sf-skills at commit 4bbae5c, republished under its Apache-2.0 licence (© forcedotcom). 2,208 words, ~5,390 tokens.

Download SKILL.mdSave it as .claude/skills/service-itsm-agentic-setup-itsm-agentforce-permset-assign/SKILL.md (or your agent's skills folder). This skill also uses 7 other files; get the full folder from GitHub.
name
service-itsm-agentic-setup-itsm-agentforce-permset-assign
description
Resolve missing ITSM Intelligence invocable actions so a Fulfiller NGA agent can activate. Reads which of the three Core Fulfiller persona permsets (IncidentFulfiller, ProblemFulfillerPermSet, ChangeRequestFulfillerPermSet) are provisioned, then assigns the running user the selected persona (plus backing PSL when license-gated) so svc_itsm_intelligence__* actions surface; hands off to service-itsm-agentic-setup-agentforce-studio-validate if none are provisioned. Use when the Fulfiller agent-configure skill reports missing actions on activate, when 'Invocable action svc_itsm_intelligence__X does not exist' surfaces, when a user asks to grant themselves Fulfiller prompt-template access, when asked to assign the Incident, Problem, or Change Fulfiller persona permission set, or when resolving missing ITSM Intelligence action access for the Fulfiller agent. DO NOT TRIGGER for Employee-agent access, Agentforce for IT Service toggles, agent creation, CMDB access, or generic permset assignment.
allowed-tools
Bash, Read, AskUserQuestion
metadata.version
1.1
metadata.domains
Service, Agentforce
metadata.minApiVersion
67.0
metadata.relatedSkills
dx-org-permission-set-assign, service-itsm-agentic-setup-agentforce-studio-validate, service-itsm-agentic-setup-cmdb-access-assign…

Assign an ITSM Fulfiller Persona Permission Set (Prompt-Template Access)

Grants the running user one of the Core-shipped Fulfiller persona permission sets that expose the svc_itsm_intelligence__* prompt-template invocable actions on the target org — the actions the Fulfiller NGA agent scripts reference via source: / target: generatePromptResponse://.... When those invocables are not surfaced by /services/data/v67.0/actions/custom/generatePromptResponse for the running user, the Fulfiller agent-configure skill's Phase 6 activate call returns HTTP 200 with a silent {success:false, messages:[{... "does not exist"}]} body and the agent never becomes usable. This skill fixes that gap by assigning the correct Fulfiller persona permset (and its backing license when one exists) — or, when no Fulfiller persona permset is provisioned on the org at all, hands off to the Agentforce Studio configure/validate skill so the ITSM AddOn(s) can be enabled first.

The three Fulfiller persona permsets, their AddOns, PSLs, and the userPerms they grant are documented in references/permset-topology.md. All are Core-shipped in namespace force — there is no managed-package namespaced permset for this feature.

Employee agent is out of scope. The Employee NGA agent's access model is separate (org-preferences + a different persona layer) and does not map onto these three persona permsets.

Every call runs through the Salesforce CLI (sf):

  • sf api request rest — authenticated Connect API GET (identity, verify read).
  • sf data query — SOQL on PermissionSet (persona presence), PermissionSetAssignment / PermissionSetLicenseAssign (idempotency).
  • sf org assign permset — assigning the permission set for the running user.
  • No token is ever extracted; no MCP is used.

Scope

  • In scope: detecting which of the three Fulfiller persona permsets (IncidentFulfiller, ProblemFulfillerPermSet, ChangeRequestFulfillerPermSet) are provisioned on the org, letting the user pick which persona to assign, checking existing assignments, assigning the permission-set license (when the persona is license-gated) and permission set to the running user (or a named user), verifying the target svc_itsm_intelligence__* invocable actions surface via a follow-up /actions/custom/generatePromptResponse read.
  • Out of scope: Employee-agent access (different access model, different skill), installing/enabling the ITSM AddOn(s) or content bundle (hand off to service-itsm-agentic-setup-agentforce-studio-validate), enabling org-level Agentforce feature toggles, creating a permission set, creating or activating the Fulfiller agent (that's service-itsm-agentic-setup-fulfiller-agent-configure), CMDB access (service-itsm-agentic-setup-cmdb-access-assign), generic non-ITSM permission-set assignment (dx-org-permission-set-assign).

Mechanism

Two branches, decided by a read-only detection step first:

  • Branch A — one or more Fulfiller persona permsets exist on the org. Ask the user which persona to assign (do not auto-select — a Fulfiller commonly needs only one). Idempotent assign: PSL first when the persona is license-gated, then permission set, verified by read-back and by a follow-up /actions/custom/generatePromptResponse read.
  • Branch B — none of the three Fulfiller persona permsets exist on the org. The ITSM AddOn(s) are not provisioned; permset-assign is a no-op. STOP and hand off to service-itsm-agentic-setup-agentforce-studio-validate so the AddOn(s) can be enabled first.

The two-branch shape is deliberate — the failure signature ("svc_itsm_intelligence__X does not exist" on activate) looks identical whether a persona is present-and-unassigned or the AddOn is absent entirely, and there is no way to tell from the activate response alone. The pre-check on the three persona PermissionSet names is what disambiguates them.

Four helper scripts (all invoked via Bash) hold every deterministic decision (A9). Full I/O contracts in references/helper-contracts.md; workflow-level usage summarized below:

  • scripts/classify-permset-availability.mjs — Branch A vs B and the per-persona needsPsl flag. Returns the full candidates[] (personas actually on the org) for the caller to prompt on.
  • scripts/resolve-target-user.mjs — extracts 005… running-user Id from the API-root identity URL. Fails closed on any malformed shape.
  • scripts/classify-assignment-state.mjs — idempotency; pass the sentinel NO-PSL in place of the PSLA path when the selected persona's needsPsl:false.
  • scripts/classify-action-surface.mjs — Phase 4 verify verdict from the /actions/custom/generatePromptResponse capture (with optional expected-actions CSV).

Preconditions

  1. sf CLI installed and authenticated to the target org (sf org display -o <alias> shows Connected). All calls use --target-org <alias>; never extract or pass the access token by hand.
  2. API v67.0+.
  3. node ≥ 18 on PATH.

If a precondition fails, sf surfaces an auth or 401/403/404; report the raw response verbatim and stop.


Clarifying questions

Ask only what cannot be inferred from conversation:

  • Target org — the sf alias. Default to sf config get target-org if unset.
  • Target user — default to the running user (resolved via scripts/resolve-target-user.mjs). If the user asks to assign on behalf of a named user, resolve them by Username first.
  • Which Fulfiller persona? Incident / Problem / Change. Only ask about personas that are actually provisioned on the org (from candidates[]). Do not auto-select — a Fulfiller commonly needs only one persona (e.g. Incident) even when others are provisioned.
  • Confirm the write — assigning a permission-set license consumes a seat and takes effect for a live user session. Present the target user + org + persona permset name, and require an explicit "yes" via AskUserQuestion before writing.

Workflow

All calls go through sf; substitute <alias> with the target org.

Phase 1 — Read: which Fulfiller persona permsets are provisioned on this org?
  1. Query PermissionSet for the three known Fulfiller persona DeveloperNames:

    bash
    sf data query \
      -q "SELECT Id, Name, Label, LicenseId FROM PermissionSet WHERE Name IN ('IncidentFulfiller','ProblemFulfillerPermSet','ChangeRequestFulfillerPermSet')" \
      --target-org <alias> --json > /tmp/itsm-personas.json 2>/tmp/itsm-personas.err || true

    (The PermissionSet namespace on all three is force — do NOT filter by NamespacePrefix.)

  2. Classify:

    bash
    node "<skill_dir>/scripts/classify-permset-availability.mjs" /tmp/itsm-personas.json

    The classifier prints { personasFound, personasMissing, candidates, verdict, reasons }, where each candidates[] row is {Id, Name, Label, LicenseId, needsPsl}:

    • verdict:"ASSIGN" (≥1 persona present) ⇒ continue to Phase 2. Present the personasFound list to the user via AskUserQuestion and get the selected persona; record its Id, LicenseId, and needsPsl — they drive whether Phase 2b/2d touch the PSL at all.
    • verdict:"HAND-OFF" (none of the three personas present) ⇒ Phase 2 is impossible on this org; go to Phase 3 (Branch B hand-off).
    • verdict:"CANNOT-CONFIRM" (query failed) ⇒ surface the raw CLI error verbatim; stop.
Phase 2 — Assign path (Branch A)

2a. Resolve the target user. Read the identity URL, then extract the user Id via the resolver (do NOT parse the URL by hand; do NOT use USER_ID() — Apex-only, rejected by REST; do NOT rely on /chatter/users/me — 403 when Chatter is off):

bash
sf api request rest "/services/data/v67.0/" --method GET --target-org <alias> > /tmp/api-root.json 2>/tmp/api-root.err || true
node "<skill_dir>/scripts/resolve-target-user.mjs" /tmp/api-root.json

The resolver prints { userId, identity, verdict, reasons }. On verdict:"RESOLVED" use userId as the running user; on verdict:"CANNOT-CONFIRM" surface the reasons verbatim and stop — do NOT guess.

If the user asks to assign on behalf of a named user instead, resolve by Username:

bash
sf data query \
  -q "SELECT Id, Username, Name, IsActive FROM User WHERE Username = '<username>'" \
  --target-org <alias> --json > /tmp/user-lookup.json 2>/tmp/user-lookup.err || true

2b. Idempotency read. Query the PermissionSetAssignment for the target user + selected persona's Id (SOQL shape in references/cli-invocation.md), and then branch on the selected persona's needsPsl:

  • needsPsl:true — query the PermissionSetLicenseAssign for the target user + the persona's LicenseId, then classify:

    bash
    node "<skill_dir>/scripts/classify-assignment-state.mjs" /tmp/psa-existing.json /tmp/psla-existing.json
  • needsPsl:false — skip the PSLA query entirely; pass the sentinel:

    bash
    node "<skill_dir>/scripts/classify-assignment-state.mjs" /tmp/psa-existing.json NO-PSL

The classifier prints { permsetAssigned, licenseAssigned, needsWrite, verdict, reasons }. If needsWrite:false ⇒ Phase 4 (verify only). Else continue to Phase 2c.

2c. Confirm-to-write checkpoint (REQUIRED). Present the target user + org + persona permset name and require an explicit "yes" via AskUserQuestion. On "no", stop and report the current state without any writes.

2d. Assign — order depends on the selected persona's needsPsl:

  • needsPsl:true — POST the PSL to /sobjects/PermissionSetLicenseAssign FIRST, then run sf org assign permset --name <permsetName> --on-behalf-of <userId>. Assigning the permission set without the PSL sticks the assignment but the license backing it never activates. Exact call shapes: references/cli-invocation.md.
  • needsPsl:false — SKIP the PSL POST entirely; run sf org assign permset only. (A persona whose PermissionSet has no backing LicenseId is not license-gated — there is no PSL seat to hold, so assigning the permset alone is the correct and complete write.) Retained defensively: every shipped persona is now PSL-backed (needsPsl is derived per-row from LicenseId), so this false branch and its NO-PSL wiring are currently unexercised by shipped data — kept for correctness against a future persona whose PermissionSet carries no backing LicenseId.

Response handling:

  • 201 on POST / success:true on sf org assign permset ⇒ assigned.
  • 400 DUPLICATE_VALUE on the PSL POST ⇒ user already had it; treat as success, not error.
  • 400 INSUFFICIENT_ACCESS / seat-exhaustion on the PSL POST ⇒ STOP for this write; tell the user the PSL has no seats available.
Show full SKILL.md (952 more words)Show less
Phase 3 — Hand-off path (Branch B: no Fulfiller persona provisioned)
  1. When Phase 1 returns verdict:"HAND-OFF", none of the three Fulfiller persona permsets exist on this org — the ITSM AddOn(s) are not provisioned. Permset-assign is a no-op in this state. Present the discovery via AskUserQuestion:

    "None of the Fulfiller persona permission sets (Incident, Problem, Change) is provisioned on this org — no permset can grant access to actions that don't exist yet. Run service-itsm-agentic-setup-agentforce-studio-validate to diagnose which AddOn needs enabling?" (options: Yes, run the readiness check / No, stop here).

    • On Yes: delegate to service-itsm-agentic-setup-agentforce-studio-validate and let it recommend the configure/bundle-deploy skill.
    • On No: stop and report the current state (no persona provisioned, cannot assign) — no writes.
Phase 4 — Verify
  1. Regardless of write vs skip, re-read /actions/custom/generatePromptResponse and classify via the helper (never by prose grep — A9). CSV shape and both invocation forms live in references/helper-contracts.md / references/cli-invocation.md:

    bash
    sf api request rest "/services/data/v67.0/actions/custom/generatePromptResponse" \
      --method GET --target-org <alias> > /tmp/generate-prompt-response.json 2>/tmp/generate-prompt-response.err || true
    node "<skill_dir>/scripts/classify-action-surface.mjs" /tmp/generate-prompt-response.json [expectedActions-csv]

    The helper prints { present, missing, totalItsmActionsSeen, verdict, reasons }. On SURFACED proceed to Phase 5; on PARTIAL / MISSING after a successful assign, tell the user the write succeeded but the actions are not surfaced — session refresh or wrong persona. Do not falsely report success. On CANNOT-CONFIRM surface the reasons verbatim.

Phase 5 — Aggregate verdict
  1. Report one of:
    • ASSIGNED — Branch A wrote, verify saw the target actions surface.
    • ALREADY-ASSIGNED — Branch A found needsWrite:false; verify saw the target actions surface. (Assignment is already in place; no writes needed.)
    • HAND-OFF — Branch B; no Fulfiller persona is provisioned. Named the follow-up skill.
    • VERIFY-INCONCLUSIVE — write completed but the verify read didn't surface the expected action set. Surface the observed state verbatim; do not report success.
    • FAILED — any Phase 2d write returned an error other than DUPLICATE_VALUE. Report the raw error.

Rules / Constraints

ConstraintRationale
Detect Fulfiller persona presence via the three fixed PermissionSet.Name values BEFORE any permset writeThe failure signature ("action does not exist" on activate) is identical for AddOn-absent and permset-not-assigned; only the pre-check disambiguates them. The three personas are Core-shipped in namespace force — a NamespacePrefix filter never returns them
Ask the user which persona to assign — never auto-selectA Fulfiller commonly needs only one persona (e.g. Incident). Auto-assigning the first row returned would over-grant
All decisions are made by helper scripts, never by proseAssignment/idempotency logic is deterministic; prose interpretation is not (A9)
Assign the PSL before the permission set — ONLY when the selected persona's needsPsl:trueThe permission set is license-backed; the license seat must be held before the assignment sticks. When the selected persona has no LicenseId, needsPsl:false and the PSL POST is skipped entirely
Read needsPsl from the SELECTED persona's LicenseId, per-row — never from a namespace-wide PSL queryDifferent personas can have different license shapes on the same org; falling back to a namespace-wide PSL would POST a wrong PermissionSetLicenseAssign
Resolve the running-user Id via scripts/resolve-target-user.mjs — never by prose parsing the identity URLThe identity URL's segment shape (005…, 15 or 18 chars) is a hard rule; the classifier validates and fails closed
Classify the Phase 4 action surface via scripts/classify-action-surface.mjs — never by prose grep of the responseVerify is the gate for reporting SUCCESS vs VERIFY-INCONCLUSIVE; the decision must be deterministic
Treat 400 DUPLICATE_VALUE on PSL POST as successIt means the user already has that assignment — idempotent, not an error
Never create or edit a permission setThis skill only assigns the standard Fulfiller persona permission set(s); authoring perm sets is out of scope
Never install the AddOn / never toggle org-level Agentforce featuresThat is the service-itsm-agentic-setup-agentforce-studio-validate / -configure scope; this skill hands off, it does not enable
Verify after write via /actions/custom/generatePromptResponse — never trust POST return code aloneThe assignment can succeed while the target action surface still doesn't include what the Fulfiller template needs (wrong persona, cache)
Confirm-to-write checkpoint before Phase 2dA permset assign consumes a license seat and takes effect for a live user session
Never extract the access tokenUse sf api request rest / sf data query / sf org assign permset — they use the CLI's stored session
Report exact error text from the CLI responseEnables support to diagnose failures

Verification Checklist

  • Persona availability classified by scripts/classify-permset-availability.mjs against the three fixed persona Names — never by prose scanning the query output.
  • User was asked to pick a persona from personasFound[] — no auto-selection.
  • Target user Id resolved by scripts/resolve-target-user.mjs — never by prose splitting the identity URL.
  • The SELECTED persona's needsPsl drove Phase 2b/2d: PSL SOQL + POST were performed when true and skipped when false.
  • permsetLicenseId used for the PSL POST came from the SELECTED persona's own LicenseId — never a fallback from a namespace-wide query.
  • On Branch A: existing assignments read via sf data query before any write, classified by scripts/classify-assignment-state.mjs (with NO-PSL sentinel when needsPsl:false).
  • On Branch A: user confirmed the write at the Phase 2c checkpoint.
  • On Branch A + needsPsl:true: PSL was POSTed before the permission set was assigned.
  • DUPLICATE_VALUE on the PSL POST was treated as success, not failure.
  • On Branch B: no write was attempted; the hand-off to service-itsm-agentic-setup-agentforce-studio-validate was offered.
  • Phase 4 verify classified via scripts/classify-action-surface.mjs — no false ASSIGNED without the helper returning verdict:"SURFACED".
  • Aggregate verdict reported (ASSIGNED / ALREADY-ASSIGNED / HAND-OFF / VERIFY-INCONCLUSIVE / FAILED).

Output Format

text
ITSM Fulfiller Persona Permset Assignment (via service-itsm-agentic-setup-itsm-agentforce-permset-assign)

Org:            <org-alias> (API v67.0)
Target user:    <username> (<userId>)
Persona:        <Incident | Problem | Change>
PermSet:        <DeveloperName>

  Personas provisioned on org ...... <comma-separated list | none>
  Existing PSL assignment .......... <yes | no | n/a>
  Existing permset assignment ...... <yes | no>
  Write PSL ........................ <succeeded | already-had | skipped | FAILED>
  Write permset .................... <succeeded | already-had | skipped | FAILED>
  Verify actions surface ........... <yes | partial | no>

Verdict: ASSIGNED | ALREADY-ASSIGNED | HAND-OFF | VERIFY-INCONCLUSIVE | FAILED
Reason:  <plain-language explanation, or empty on success>

Next steps:
  - <If ASSIGNED / ALREADY-ASSIGNED: "Re-run service-itsm-agentic-setup-fulfiller-agent-configure — the invocable actions should now surface, and the activate call will succeed.">
  - <If HAND-OFF: "No Fulfiller persona is provisioned on this org. Run service-itsm-agentic-setup-agentforce-studio-validate to identify which AddOn needs enabling.">
  - <If VERIFY-INCONCLUSIVE: list the observed state verbatim; a session refresh or a different persona may be required>
  - <If FAILED: list the observed error verbatim + remediation>

Keep internal jargon (record Ids, HTTP status codes, FUNCTIONALITY_NOT_ENABLED, DUPLICATE_VALUE, object/developer names, sf api request rest) out of user-facing output.


Reference File Index

FileWhen to read
references/permset-topology.mdAny change to the persona list — the three Core-shipped Fulfiller permsets, their AddOns/PSLs/userPerms, and the fixed-lookup discovery query
references/cli-invocation.mdEvery phase — exact sf api request rest / sf data query / sf org assign permset call shapes, the never-extract-token rule, response envelopes
references/helper-contracts.mdThe input/output shapes of all four helper scripts (classify-permset-availability.mjs, resolve-target-user.mjs, classify-assignment-state.mjs, classify-action-surface.mjs) and how to interpret each verdict

© forcedotcom, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 7 other files (scripts, references) in skills/service-itsm-agentic-setup-itsm-agentforce-permset-assign of forcedotcom/sf-skills.

  • SKILL.md
  • references/cli-invocation.md
  • references/helper-contracts.md
  • references/permset-topology.md
  • scripts/classify-action-surface.mjs
  • scripts/classify-assignment-state.mjs
  • scripts/classify-permset-availability.mjs
  • scripts/resolve-target-user.mjs

Open the folder on GitHubat commit 4bbae5c

Compare with similar skills

Service Itsm Agentic Setup Itsm Agentforce Permset Assign next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Service Itsm Agentic Setup Itsm Agentforce Permset Assign compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Service Itsm Agentic Setup Itsm Agentforce Permset Assign this skillforcedotcom/sf-skills1.1k—~5.4kAutomated safety check: NotesApache-2.0
Prompt Improverseverity1/claude-code-prompt-improver1.9k1 repos~1.7kAutomated safety check: PassMIT
Prompt Engineering Patternsynulihao/AgentSkillOS61814 repos~1.7kAutomated safety check: PassNone
Patch CreationPiebald-AI/tweakcc2.5k—~1.6kAutomated safety check: PassMIT
Senior Prompt Engineermaslennikov-ig/claude-code-orchestrator-kit2603 repos~1.4kAutomated safety check: PassCustom licence
Codex Fable5baskduf/FableCodex437—~1.6kAutomated safety check: PassAGPL-3.0

Similar skills

  • Prompt Improver

    severity1/claude-code-prompt-improver

    This skill enriches vague prompts with targeted research and clarification before execution.

    1.9k GitHub starsUsed in 1 repo~1.7k tokens
    AI & LLM EngineeringAuto-check passed
  • Prompt Engineering Patterns

    ynulihao/AgentSkillOS

    Master advanced prompt engineering techniques to maximize LLM performance, reliability, and controllability in production.

    618 GitHub starsUsed in 14 repos~1.7k tokens
    AI & LLM EngineeringAuto-check passed
  • Patch Creation

    Piebald-AI/tweakcc

    Create and register new patches for tweakcc. An agent skill from Piebald-AI/tweakcc.

    2.5k GitHub stars~1.6k tokensUpdated yesterday
    AI & LLM EngineeringAuto-check passed
  • Senior Prompt Engineer

    maslennikov-ig/claude-code-orchestrator-kit

    Provides reference guides and Python scripts for prompt optimization, RAG evaluation, and agent orchestration when building or tuning LLM systems.

    260 GitHub starsUsed in 3 repos~1.4k tokens
    AI & LLM EngineeringAuto-check passed
  • Codex Fable5

    baskduf/FableCodex

    Apply a Claude Fable 5 inspired operating style inside Codex.

    437 GitHub stars~1.6k tokensUpdated 2 mo ago
    AI & LLM EngineeringAuto-check passed
  • Reference for designing and tuning production LLM prompts: few-shot examples, chain-of-thought, structured outputs, templates and system prompts.

    40k GitHub stars~1.3k tokensUpdated 6 days ago
    AI & LLM EngineeringAuto-check passed

More from forcedotcom/sf-skills

All 252 skills in this repo
  • Agentforce Architecture Analyze

    forcedotcom/sf-skills

    Declared architecture snapshot for one Agentforce agent: planner, topics, actions, flows, Apex, prompt templates, and NGA plugins.

    1.1k GitHub stars~4.5k tokensUpdated yesterday
    Auto-check passed
  • Agentforce D360 Analyze

    forcedotcom/sf-skills

    Data Cloud 360° view of a single Agentforce session. An agent skill from forcedotcom/sf-skills.

    1.1k GitHub stars~3.4k tokensUpdated yesterday
    Auto-check passed
  • Apply a Salesforce sandbox post-copy automation JSON config against a target org.

    1.1k GitHub stars~5.3k tokensUpdated yesterday
    Auto-check: notes
  • Apply a Salesforce sandbox post-copy automation JSON config against a target org.

    1.1k GitHub stars~5.4k tokensUpdated yesterday
    Auto-check: notes
  • Design Systems Slds Apply

    forcedotcom/sf-skills

    Apply SLDS-compliant UI using the correct blueprints, styling hooks, utility classes, and icons.

    1.1k GitHub stars~3.7k tokensUpdated yesterday
    Auto-check passed
  • Experience Lwc Generate

    forcedotcom/sf-skills

    Lightning Web Components with PICKLES methodology and 165-point scoring.

    1.1k GitHub stars~2.4k tokensUpdated yesterday
    Auto-check passed

Works with

Questions about Service Itsm Agentic Setup Itsm Agentforce Permset Assign

What does Service Itsm Agentic Setup Itsm Agentforce Permset Assign do?

Resolve missing ITSM Intelligence invocable actions so a Fulfiller NGA agent can activate. Service Itsm Agentic Setup Itsm Agentforce Permset Assign is an agent skill from forcedotcom/sf-skills. Resolve missing ITSM Intelligence invocable actions so a Fulfiller NGA agent can activate.

When should I use Service Itsm Agentic Setup Itsm Agentforce Permset Assign?

Service Itsm Agentic Setup Itsm Agentforce Permset Assign fits situations like: the Fulfiller agent-configure skill reports missing actions on activate; invocable action svcitsmintelligenceX does not exist surfaces; A user asks to grant themselves Fulfiller prompt-template access; asked to assign the Incident.

How do I install Service Itsm Agentic Setup Itsm Agentforce Permset Assign in Claude Code?

Run `npx skills add forcedotcom/sf-skills --skill service-itsm-agentic-setup-itsm-agentforce-permset-assign -a claude-code`. Or copy the skill folder (skills/service-itsm-agentic-setup-itsm-agentforce-permset-assign in forcedotcom/sf-skills) into .claude/skills/service-itsm-agentic-setup-itsm-agentforce-permset-assign in your project. Claude Code loads it when a task matches its description.

How do I install Service Itsm Agentic Setup Itsm Agentforce Permset Assign in Codex?

Run `npx skills add forcedotcom/sf-skills --skill service-itsm-agentic-setup-itsm-agentforce-permset-assign -a codex`. Or copy the skill folder (skills/service-itsm-agentic-setup-itsm-agentforce-permset-assign in forcedotcom/sf-skills) into .agents/skills/service-itsm-agentic-setup-itsm-agentforce-permset-assign in your project. Codex loads it when a task matches its description.

Can I use Service Itsm Agentic Setup Itsm Agentforce Permset Assign in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add forcedotcom/sf-skills --skill service-itsm-agentic-setup-itsm-agentforce-permset-assign -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/service-itsm-agentic-setup-itsm-agentforce-permset-assign, .gemini/skills/service-itsm-agentic-setup-itsm-agentforce-permset-assign, .github/skills/service-itsm-agentic-setup-itsm-agentforce-permset-assign and .opencode/skills/service-itsm-agentic-setup-itsm-agentforce-permset-assign in your project.

What does Service Itsm Agentic Setup Itsm Agentforce Permset Assign need to run?

Going by SKILL.md and its folder, Service Itsm Agentic Setup Itsm Agentforce Permset Assign needs JavaScript for the scripts in its folder and the command-line tools its instructions call (sf and node). Our summary lists: Node.js. Its frontmatter pre-approves these tools: Bash, Read, AskUserQuestion.

Does Service Itsm Agentic Setup Itsm Agentforce Permset Assign access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Service Itsm Agentic Setup Itsm Agentforce Permset Assign safe to install?

Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Service Itsm Agentic Setup Itsm Agentforce Permset Assign use?

Service Itsm Agentic Setup Itsm Agentforce Permset Assign is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Service Itsm Agentic Setup Itsm Agentforce Permset Assign use?

About 5.4k tokens (SKILL.md is roughly 22k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 4.2k tokens, read only when the agent opens those files.

What are the alternatives to Service Itsm Agentic Setup Itsm Agentforce Permset Assign?

Skills that share tags, products or a category with Service Itsm Agentic Setup Itsm Agentforce Permset Assign: Prompt Improver (severity1/claude-code-prompt-improver, 1.9k stars), Prompt Engineering Patterns (ynulihao/AgentSkillOS, 618 stars), Patch Creation (Piebald-AI/tweakcc, 2.5k stars) and Senior Prompt Engineer (maslennikov-ig/claude-code-orchestrator-kit, 260 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Service Itsm Agentic Setup Itsm Agentforce Permset Assign?

forcedotcom (a GitHub organization) maintains it in forcedotcom/sf-skills, which has 1,067 GitHub stars. The repository holds 252 skills in this directory. The repository was last updated on October 9, 2026.

Source: forcedotcom/sf-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.